Insecure Default Permissions in Ivanti Endpoint Manager Agent
CVE-2025-10918

7.1HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
11 November 2025

What is CVE-2025-10918?

An issue has been identified in Ivanti Endpoint Manager versions before 2024 SU4, where the agent is configured with insecure default permissions. This flaw permits a local authenticated attacker to write arbitrary files anywhere on the disk, potentially leading to unauthorized access and manipulation of system resources.

Affected Version(s)

Endpoint Manager 2024 SU4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-10918 : Insecure Default Permissions in Ivanti Endpoint Manager Agent